redact-secret · Report
API token
r8_ prefixed API token; the provider documents a 40-character total (a 37-character body) and does not state the body alphabet.
Research record
3 events in the review history: 2 observed, 1 reviewed. Latest: observed on 2026-09-24 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.
Format
What it looks like
- Descriptive pattern
^r8_[A-Za-z0-9_-]{37}$
Parts are shown as recorded. Evidence classes belong to the facts below; no class is assigned to a part.
Format facts
Provider documented ·
provider-source· current · observed 2026-09-24Replicate API tokens page ("40-character strings that always start with r8_"): Replicate states that API tokens are 40-character strings that always start with r8_, fixing the prefix and a 37-character body. The page states no body alphabet.
- replicate.com/docs/topics/security/api-tokensprovider-documentation · last read 2026-09-24 · latest outcome read · supports Replicate states that API tokens are 40-character strings that always start with r8_, fixing the prefix and a 37-character body. The page states no body alphabet.
Unresolved ·
tool-corroboration· current · observed 2026-09-24Pinned scanner rules are consistent with the contract grammar (1 artifact: trufflehog 3.97.4).
- trufflesecurity/trufflehog @ v3.97.4: pkg/detectors/replicate/replicate.goscanner-rule-source · last read 2026-09-24 · latest outcome read · supports trufflehog 3.97.4: Replicate: \b(r8_[0-9A-Za-z-_]{37})\b
Provider documented ·
field-prefix· current · observed 2026-09-24prefix: r8_
- replicate.com/docs/topics/security/api-tokensprovider-documentation · last read 2026-09-24 · latest outcome read · supports prefix: r8_
Provider documented ·
field-total-length· current · observed 2026-09-24total-length: 40 characters (37-character body after r8_)
- replicate.com/docs/topics/security/api-tokensprovider-documentation · last read 2026-09-24 · latest outcome read · supports total-length: 40 characters (37-character body after r8_)
Tool corroborated ·
field-body-alphabet· current · observed 2026-09-24body-alphabet: [A-Za-z0-9] in every positive; TruffleHog also admits - and _, flare-redact and agent-sweep admit alphanumerics only (The provider does not state a charset. The contract pattern admits the union so only a non-word byte counts as an alphabet mutation.)
- flare-collection/flare-redact @ c652ea7946028b70527069d7c282752b8a0ccee3: spec/detectors.jsonscanner-rule-source · last read 2026-09-24 · latest outcome read · supports r8_[A-Za-z0-9]{30,45} · #L1352
- trufflesecurity/trufflehog @ v3.97.4: pkg/detectors/replicate/replicate.goscanner-rule-source · last read 2026-09-24 · latest outcome read · supports body class [0-9A-Za-z-_]{37}; its own test fixture is alphanumeric
Provider documented ·
field-header-scheme· current · observed 2026-09-24header-scheme: Authorization: Bearer <token>; the legacy Authorization: Token <token> is still accepted
- replicate.com/changelog/2024-04-03-bearer-tokensprovider-documentation · last read 2026-09-24 · latest outcome read · supports header-scheme: Authorization: Bearer <token>; the legacy Authorization: Token <token> is still accepted
- replicate.com/docs/reference/httpprovider-documentation · last read 2026-09-24 · latest outcome read · supports header-scheme: Authorization: Bearer <token>; the legacy Authorization: Token <token> is still accepted
Unresolved ·
field-sibling-tokens· current · observed 2026-09-24sibling-tokens: Whether the cog login token (replicate.com/auth/token) or org-owned and default tokens differ in shape from a created API token
- docs.gitguardian.com/secrets-detection/secrets-detection-engine/detectors/specifics/replicate_user_access_tokenother · last read 2026-09-24 · latest outcome read · supports sibling-tokens: Whether the cog login token (replicate.com/auth/token) or org-owned and default tokens differ in shape from a created API token
- replicate/cog @ main: pkg/cli/login.goother · last read 2026-09-24 · latest outcome read · supports sibling-tokens: Whether the cog login token (replicate.com/auth/token) or org-owned and default tokens differ in shape from a created API token
Unresolved ·
listed-references· current · observed 2026-09-24The legacy contract lists 3 references without stating which property each supports.
- replicate/replicate-python @ main: replicate/client.pyother · last read 2026-09-24 · latest outcome read · supports Listed as a reference by the legacy contract
- replicate.com/changelog/2024-04-03-bearer-tokensprovider-documentation · last read 2026-09-24 · latest outcome read · supports Listed as a reference by the legacy contract
- replicate.com/docs/reference/httpprovider-documentation · last read 2026-09-24 · latest outcome read · supports Listed as a reference by the legacy contract
Provider documented ·
dossier-research· current · observed 2026-09-24Legacy dossier research (verdict ready, tier T1) cited 3 sources; the dossier does not attribute sources to individual properties.
- redact-secret/redact-secret @ 8b6a5fde52ecb4dfce13f09c7a947062d21483c7: docs/audits/evidence/726/README.mdproject-research-note · last read 2026-09-27 · latest outcome read · supports Final research evidence recorded by the legacy dossier
- replicate.com/changelog/2024-04-03-bearer-tokensprovider-documentation · last read 2026-09-24 · latest outcome read · supports Cited by the legacy dossier research for this family
- replicate.com/docs/topics/security/api-tokensprovider-documentation · last read 2026-09-24 · latest outcome read · supports Cited by the legacy dossier research for this family
Provider documented ·
taxonomy-sources· current · observed 2026-09-24The legacy taxonomy lists 2 sources for this family. The taxonomy records no date; the dossier researchedAt is used as the observed-at date.
- replicate.com/changelog/2024-04-03-bearer-tokensprovider-documentation · last read 2026-09-24 · latest outcome read · supports Listed as a source for this family in the legacy taxonomy
- replicate.com/docs/topics/security/api-tokensprovider-documentation · last read 2026-09-24 · latest outcome read · supports Listed as a source for this family in the legacy taxonomy
Open questions
No open question is recorded for this revision.
Benchmark dossier notes
- Shape
- prefix
r8_, 40 characters in total (a 37-character body). The provider states the prefix and the total length. It states no body alphabet. TruffleHog accepts letters, digits,-and_; flare-redact accepts letters and digits only. No checksum or embedded account id is documented. - Basis
- T1 for prefix and length (the API-tokens page). Alphabet: scanner rules only, contested. Both
Authorization: Bearerand the olderAuthorization: Tokenheader are accepted (2024-04-03 changelog), and the docs show a masked example (r8_, two visible characters, asterisks). - Issuance
- not attempted. Free accounts can create tokens. Replicate scans public GitHub repositories for committed tokens and disables the ones it finds (it joined the GitHub Secret Scanning Partner Program in 2024-04).
- Contract in core
- detector-families.md (Beta.8 arrival contracts, frozen in the #726 record linked above; the provider-stated length is exact and the alphabet is provisional).
In this benchmark
- Fixtures
- 32
- Left readable
- 0
- Redacted too much
- 0
- False alarms
- 0
32 fixtures: 12 expect a redaction, 20 must stay quiet. See every row
| Evidence level | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| T1Provider-documented | 12 | 0 | 0 | 0 |
| T2Tool-corroborated | 13 | 0 | 0 | 0 |
| T3Project policy | 7 | 0 | 0 | 0 |
Every scanner on the same fixtures
In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.
| Scanner | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engine1 rule targets it | 32 | 0 | 0 | 1 |
| gitleaksRepository scanner · 8.30.1 · Directory scan · default rulesNo rule maps to it | 32 | 6 | 0 | 1 |
| redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectors1 detector mapped | 32 | 0 | 0 | 0 |
| trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabled1 rule targets it | 32 | 0 | 0 | 0 |
Benchmark dossier questions
- Open caveat
- Body alphabet is not provider-stated (TruffleHog admits - and _, flare-redact does not); one issued token would settle it (checklist in benchmarks#217).
Looks like it, but isn't
- Collisions
r8.im/<owner>/<model>container registry references and 64-hex model version ids are public and share ther8stem or sit next to tokens. Thecog logintoken fromreplicate.com/auth/tokenmay be a different credential; the relation is undocumented and not claimed.
Scanner rules for this family
| Scanner | Rule | What the rule matches |
|---|---|---|
| flare-redact · rules 1.6.1 | replicate_token | r8_ + 30-45 characters |
| trufflehog · rules 3.97.4 | replicate | r8_ + 37 characters |
No rule maps to this family in gitleaks, openredaction.
Fixtures in this family
| Fixture | Kind and evidence | redact-secret |
|---|---|---|
replicate-api-token-bearer-long-body-twinreplicate · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
replicate-api-token-chat-pastereplicate · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
replicate-api-token-env-short-body-twinreplicate · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
replicate-api-token-go-sdkreplicate · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
replicate-api-token-legacy-token-headerreplicate · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
replicate-api-token-token-shape-barereplicate · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
replicate-api-token-token-shape-quotedreplicate · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
replicate-api-token-token-shape-unicode-crlfreplicate · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
replicate-api-token-actions-literalreplicate · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
replicate-api-token-actions-secret-referencereplicate · templated-reference | Must not flagT3 · Project policy | Quiet |
replicate-api-token-base64-input-encoded-valuereplicate · benign-encoded-value | Must not flagT2 · Tool-corroborated | Quiet |
replicate-api-token-bearer-headerreplicate · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
replicate-api-token-docs-prosereplicate · prose-mention | Must not flagT3 · Project policy | Quiet |
replicate-api-token-envreplicate · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
replicate-api-token-env-template-placeholderreplicate · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
replicate-api-token-go-uppercase-prefix-twinreplicate · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
replicate-api-token-identifier-near-missreplicate · format-near-miss | Must not flagT2 · Tool-corroborated | Quiet |
replicate-api-token-label-prosereplicate · benign-lookalike | Must not flagT3 · Project policy | Quiet |
replicate-api-token-maskreplicate · benign-lookalike | Must not flagT3 · Project policy | Quiet |
replicate-api-token-masked-docs-placeholderreplicate · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
replicate-api-token-mcp-configreplicate · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
replicate-api-token-mcp-hyphen-prefix-twinreplicate · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
replicate-api-token-model-version-public-idreplicate · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
replicate-api-token-prefix-onlyreplicate · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
replicate-api-token-printenvreplicate · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
replicate-api-token-printenv-glued-twinreplicate · boundary-violation | Must not flagT2 · Tool-corroborated · twin | Quiet |
replicate-api-token-python-dot-body-twinreplicate · wrong-alphabet | Must not flagT2 · Tool-corroborated · twin | Quiet |
replicate-api-token-python-sdkreplicate · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
replicate-api-token-referencereplicate · benign-lookalike | Must not flagT3 · Project policy | Quiet |
replicate-api-token-registry-image-public-idreplicate · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
replicate-api-token-short-bodyreplicate · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
replicate-api-token-truncated-near-missreplicate · format-near-miss | Must not flagT2 · Tool-corroborated | Quiet |
Sources
Documentation and code
- replicate.com/docs/topics/security/api-tokens
- replicate.com/changelog/2024-04-03-bearer-tokens
Research log
- redact-secret/redact-secret-benchmarks#215Research issue
- redact-secret/redact-secret-benchmarks#217Research issue
- redact-secret/redact-secret#726Research issue
- redact-secret/redact-secret#727Research issue
- Final evidence, pinned to a commit/redact-secret/redact-secret/blob/8b6a5fde52ecb4dfce13f09c7a947062d21483c7/docs/audits/evidence/726/README.md